Commands for iOS and iPadOS devices

Command

Description

Activation types

View device report

This command displays detailed information about a device. You can export and save the device report.

MDM controls

User privacy

View device actions

This command displays any actions that are in progress on a device.

MDM controls

User privacy

Delete all device data

This command deletes all user information and app data that the device stores and returns the device to factory default settings.

If the device is unable to connect to BlackBerry UEM when you send this command, you can either cancel the command or remove the device from the console. If the device connects to UEM after you remove it, only the work data is deleted from the device.

If you send the command to devices with iOS 17 or later, you can select the “Enable Return to Service” option and select a Wi-Fi profile to assign to the devices to assist the user in setting up the device again after data is deleted.

If eSIM information is detected on one or more devices that you select, you are prompted to specify whether the data plan information must be preserved.

MDM controls

Delete only work data

This command deletes work data, including the IT policy, profiles, apps, and certificates that are on the device.

If the device is unable to connect to UEM when you send this command, you can either cancel the command or remove the device from the console. If the device connects to UEM after you remove it, the work data is deleted from the device.

MDM controls

User privacy

Lock device

This command locks a device. Apple appends "Lost iPhone" or "Lost iPad" to the title of the message you specify. The user must type the existing device password to unlock the device.

When you send this command, the device locks only if there is an existing device password. Otherwise, no action is taken on the device.

This command is not supported for Apple TV devices.

MDM controls

Unlock and clear password

This command unlocks a device and deletes the existing password. The user is prompted to create a device password. You can use this command if the user forgets the device password.

This command is not supported for Apple TV devices.

MDM controls

Turn on Lost Mode

This command locks the device and allows you to display a phone number and message on the device. After you send this command you can view the location of the device in the management console.

This command is supported for supervised devices only. This command is not supported for Apple TV devices.

MDM controls

Deactivate BlackBerry 2FA

This command deactivates devices that are activated with the BlackBerry 2FA activation type. The device is removed from UEM and the user can't use the BlackBerry 2FA feature.

This command is not supported for Apple TV devices.

MDM controls

Update OS

This command forces devices to install an available OS update.

This command is supported for supervised devices only. This command is not supported for Apple TV devices.

MDM controls

Restart device

This command forces the device to restart.

This command is supported for supervised devices only. This command is not supported for Apple TV devices.

MDM controls

Turn off device

This command forces the device to turn off.

This command is supported for supervised devices only. This command is not supported for Apple TV devices.

MDM controls

Wipe apps

This command wipes data from all Microsoft Intune managed apps on the device. The apps are not removed from the device.

MDM controls

Update device information

This command sends and receives updated device information. For example, you can send newly updated IT policy rules or profiles to a device, and receive updated information about a device such as OS version or battery level.

MDM controls

User privacy

Update time zone

This command sets the device time according to the region that you select.

MDM controls

Remove device

This command removes the device from UEM but does not remove data from the device. The device may continue to receive email and other work data.

This command is intended for devices that have been irretrievably lost or damaged and are not expected to contact the server again. If a device that has been removed attempts to contact UEM, the user receives a notification and the device won't be able to communicate with UEM unless it is reactivated.

MDM controls

User privacy

Refresh eSIM

For devices that have an eSIM-based cellular plan, this command queries updated plan details for the device from the device carrier URL.

MDM controls